Perito Camión
  • Specialities
  • Who I help
  • The difference
  • Who I am
  • What you get
  • Method
  • Quotation
  • FAQ
  • Tell me about your case
  • English
  • Spanish
  • Catalan
  • Basque
  • Galician
Tell me about your case

Data Processing Agreement (DPA)

This Data Processing Agreement (hereinafter, the «DPA» or «Agreement») governs the relationship between the client engaging or using Perito Camión services (hereinafter, the «Controller») and Perito Camión (hereinafter, the «Processor») where the Controller uses the services to process personal data of third parties.

This DPA is signed electronically upon acceptance of the service terms and forms an integral part of them. It applies automatically and is deemed accepted when the Controller first enters a third party’s personal data into the tool.

Scope. This DPA applies only to party-commissioned engagements. In court-appointed expert work (Art. 341 of the Spanish Civil Procedure Act), the expert does not act on behalf of the client: he is an officer assisting the court with obligations of his own and acts as data controller, so this Agreement does not apply to such engagements.

1. Parties and definitions

On the one hand, the Data Controller is the client, whether a natural or legal person, who engages or uses Perito Camión and uploads to the platform personal data of third parties over which it holds ownership or a legitimate interest in the processing.

On the other hand, the Data Processor is Pedro Mulero Sánchez, court-appointed expert and member of Aspejure, Spanish tax ID 43700194X, contact address privacidad@tarracoapplab.com. «Perito Camión» is the trade name under which the service is provided, owned by Tarraco App Lab, S.L.U.

The definitions in Article 4 of Regulation (EU) 2016/679 (GDPR) and in Spanish Organic Law 3/2018 on Data Protection and the Guarantee of Digital Rights (LOPDGDD) apply.

2. Subject matter, duration and nature of the processing

Subject matter. Processing by the Processor, on behalf of the Controller, of the personal data the Controller uploads to the Perito Camión platform for the provision of the services engaged.

Duration. The duration of the processing coincides with the duration of the contractual service relationship, subject to any subsequent mandatory legal retention.

Nature. Automated processing on cloud infrastructure, with encryption in transit and at rest, in accordance with the technical and organisational measures described in clause 6.

Purpose. Solely the technical analysis of the documentation, the preparation of the report commissioned and, where applicable, its ratification before the relevant body.

3. Categories of data and of data subjects

The categories of personal data processed and the data subjects affected vary according to the engagement. The most common are:

3.1. Employment and tachograph documentation

  • Data subjects: drivers and other staff of the company concerned.
  • Identification data: first name, surname, national ID number, driver card number.
  • Employment data: job category, collective agreement, working time, payslips, work calendar, working-time records and digital tachograph files.

3.2. Claims and valuation documentation

  • Data subjects: owners, drivers and third parties involved.
  • Data: identification of the vehicle and its owner, police reports, workshop reports, photographs and previous appraisals.

3.3. Court documentation

  • Data subjects: parties and witnesses in the proceedings.
  • Data: that contained in pleadings, rulings and documentary evidence submitted.

The Controller undertakes not to upload to the platform special categories of data (racial origin, health, ideology, sex life or orientation, genetic or biometric data) except where strictly necessary and with an appropriate legal basis, and to notify the Processor in advance so that the corresponding enhanced measures can be activated.

4. Obligations of the Processor (Perito Camión)

The Processor undertakes to:

  • Process personal data only in accordance with the Controller’s documented instructions, including those relating to international transfers (which are deemed documented in the contract and in this DPA), unless required to do otherwise by Union or Member State law, in which case it will notify the Controller before processing, unless legally prohibited.
  • Ensure that personnel with access to the data have committed themselves to confidentiality, through a contractual undertaking and periodic training. The duty of confidentiality survives termination of the relationship.
  • Adopt the technical and organisational measures required by Art. 32 GDPR, as detailed in clause 6.
  • Not subcontract the processing to third parties without the Controller’s prior authorisation, whether general or specific. Signature of this DPA constitutes general authorisation for the sub-processors listed in clause 5, with the Controller retaining the right to object to the addition of new sub-processors.
  • Assist the Controller with appropriate technical and organisational measures in responding to data subjects’ rights (access, rectification, erasure, restriction, objection, portability). Where a data subject addresses a request to the Processor, it will be forwarded to the Controller within a maximum of 5 calendar days.
  • Assist the Controller in complying with its obligations under Arts. 32 to 36 GDPR (security, breaches, impact assessments and prior consultation).
  • Notify the Controller without undue delay and, in any event, within a maximum of 48 hours of becoming aware of any personal data breach. The notification will describe the nature of the breach, the data and categories of data subjects affected, the likely consequences and the measures taken or proposed.
  • Make available to the Controller, upon reasonable request and with at least 4 weeks’ notice, all information necessary to demonstrate compliance with Art. 28 GDPR, and allow audits once a year, during business hours and in a manner that does not interrupt service provision. For audits of technical measures, an independent auditor’s report (ISO 27001, SOC 2 or equivalent) may be provided if current.
  • Return or delete, at the Controller’s choice, all personal data once the service has ended, except for copies strictly required by applicable law (taxation, limitation of actions). Return will be made in a structured, commonly used format (CSV, JSON) and deletion will be documented in writing. The maximum period from termination of the contract is 90 calendar days.

5. Authorised sub-processors

The Controller grants the Processor general authorisation to use the following sub-processors, all bound by a GDPR-compatible contract:

Processing is carried out locally, on the expert's own equipment: case file documentation is not uploaded to third-party cloud services. Accordingly, no sub-processors are generally used for the processing of case file data. The website infrastructure (Netlify, United States, under standard contractual clauses) is used solely for the contact form and plays no part in the processing of expert documentation. Should a particular engagement require the involvement of a third party (laboratory, workshop or specialist), prior written authorisation would be sought from the Controller.

The Processor will give the Controller at least 30 calendar days’ notice of any addition or replacement of a sub-processor. The Controller may object on reasoned grounds within that period and, if the objection is reasonable, the Processor must offer an alternative or the Controller may terminate the contract without penalty.

6. Technical and organisational measures (Art. 32 GDPR)

6.1. Encryption

  • TLS 1.2/1.3 mandatory on all communications. HSTS enabled.
  • AES-256 at rest for the storage bucket and the PostgreSQL database.
  • Passwords hashed with bcrypt or equivalent.

6.2. Access control

  • Row-Level Security in the database: each user can only access their own data.
  • Rotatable and revocable API keys. Session tokens with expiry.
  • Administrative access by the Processor with mandatory multi-factor authentication.
  • Least-privilege principle for all administrative access.

6.3. Resilience and availability

  • Automatic backups with 7 to 30 days’ retention depending on plan.
  • Infrastructure with the cloud provider’s availability SLA.
  • Basic continuity plan with recovery time objective (RTO) <24h and recovery point objective (RPO) <24h.

6.4. Staff confidentiality

  • Perpetual confidentiality undertaking signed by anyone with access to systems.
  • Periodic training in data protection and security.
  • Revocation of access upon termination of the employment relationship.

6.5. Verification and auditing

  • Periodic review of logs and dependencies (lockfiles, vulnerability alerts).
  • Penetration testing whenever a new critical component is introduced.
  • Internal register of incidents and breaches with analysis and corrective measures.

7. International transfers

No international transfers of expert documentation take place: processing is carried out entirely in Spain, locally. Should it become necessary at any point to use a provider located outside the EEA, the safeguards in Chapter V GDPR would be applied and the Controller would be informed in advance.

8. Security breach — detailed procedure

In the event of a breach affecting the Controller’s personal data:

  1. The Processor will make an internal record of the incident with a detection timestamp.
  2. Within a maximum of 48 hours it will notify the Controller by email at the designated contact, with a full description of the incident.
  3. The Processor will immediately adopt reasonable corrective measures and keep the Controller informed of developments.
  4. The Controller will decide whether notification to the AEPD (Art. 33 GDPR) and to data subjects (Art. 34 GDPR) is appropriate. The Processor will provide technical and documentary assistance for that notification.
  5. Following resolution, both parties will document the lessons learned and any additional measures adopted.

9. Audit

The Controller may audit compliance with this DPA once a year, with at least 4 weeks’ prior written notice, during business hours and without interrupting service provision. To minimise the impact, the Processor may offer the Controller a current external audit report (ISO 27001, SOC 2 or equivalent). The costs of the audit are borne by the Controller, unless the audit reveals material breaches by the Processor, in which case the Processor will bear them.

10. Liability and financial arrangements

Each party is liable for damage arising from a breach of its obligations, in accordance with Art. 82 GDPR and other applicable legislation. The limitation of liability and indemnity regime is governed by the general terms of service. The Processor will maintain professional civil liability insurance appropriate to the volume of the service.

11. Duration and termination

This DPA remains in force for as long as the Controller’s contractual relationship with Perito Camión for the processing of third-party personal data continues. Termination of the main contract entails termination of the DPA, without prejudice to obligations that by their nature survive (perpetual staff confidentiality, legal data retention).

12. Changes

The Processor may modify this DPA where required by a change in legislation or a substantial improvement in security measures. Changes will be published on this page with the revision date and notified to the Controller with reasonable notice. The Controller may object on reasoned grounds; if the objection is not resolved by agreement, it may terminate the contract without penalty.

13. Applicable law and jurisdiction

This DPA is governed by Spanish law (GDPR, LOPDGDD and other applicable legislation). The parties submit, expressly waiving any other jurisdiction, to the competent Courts and Tribunals of Spain in accordance with the applicable procedural rules.

Last updated: July 2026.

Perito Camión
  • Specialities
  • Contact
  • Legal notice
  • Privacy
  • Cookies
  • Terms of use
  • Data Processing Agreement
© 2026 Perito Camión · All rights reserved · Website/App developed, with AI tools, by the web design team at Tarraco App Lab, in Spain